Stunnel 4.00 and versions 3.24 and earlier leak a privileged file descriptor returned by listen(), allowing local users to hijack the stunnel server.

Our supporters:
Go to the top